Skip to main content

Privacy Policy

How we collect, use, and protect your information.

Last updated: October 5, 2026

Who We Are

JonesLabs LLC ("JonesLabs," "we," "us," or "our") is a small software company based in Atlanta, Georgia. This privacy policy explains how we collect, use, and protect information when you visit joneslabs.dev (the "Site") and when you use our native applications for iPhone, iPad, Mac, and Apple Watch (the "Apps").

Information We Collect

Contact Form Submissions

When you submit our contact form, we collect the information you provide: your name, email address, phone number (optional), and message. This information is sent to us via email through Resend, our email delivery provider, and is used solely to respond to your inquiry.

Automatically Collected Information

We automatically collect certain information when you visit the Site:

  • IP addresses are processed temporarily for rate limiting on the contact form (limited to 3 submissions per 15 minutes). IP addresses are stored in server memory only and are not persisted to any database or log file. They are cleared when the server restarts.
  • Analytics data is collected through Umami (self-hosted). Umami is a privacy-focused, cookie-free analytics platform hosted on our own infrastructure. No personal data is collected or shared with third parties. Analytics data includes pages visited, referring URLs, browser type, device type, and general geographic location. This data is aggregated and used to understand how visitors use the Site.

Local Storage

We store a single preference in your browser's local storage (joneslabs-dark-mode) to remember your dark mode setting. This is not a cookie, is never sent to our servers, and contains no personal information.

How We Use Your Information

We use the information we collect to:

  • Respond to your contact form inquiries
  • Send you a confirmation email when you submit the contact form
  • Protect the Site from spam and abuse (rate limiting, bot detection)
  • Understand how visitors use the Site so we can improve it

We do not sell, rent, or share your personal information with third parties for marketing purposes.

Third-Party Services

We use the following third-party services that may process data on our behalf:

Cookies

We do not set any first-party cookies. Our analytics provider (Umami) is cookie-free. However, third-party services we use (Cloudflare) may set their own cookies to provide security features. You can control cookie behavior through your browser settings.

Our iOS & macOS Apps

JonesLabs builds native apps for iPhone, iPad, Mac, and Apple Watch. Unless a specific app is called out otherwise below, every JonesLabs app follows the same rules:

  • No data collection. Our apps contain no analytics SDKs, no advertising, and no trackers. We do not collect, transmit, or store your personal information or your content.
  • No JonesLabs accounts or servers. Our apps do not require an account with us. Your content stays on your device (and in your personal iCloud account if an app offers iCloud sync), and we never see it.
  • Purchases are handled by Apple. App and in-app purchases are processed entirely by the App Store. We receive aggregated sales reports from Apple and never see your payment details or identity.
  • Support. If you contact us about an app, we handle your message the same way as contact form submissions described above.

SereneReader

SereneReader is the exception to the "no accounts or servers" rule above: it is a feed reading service with native apps. It requires a SereneReader account and syncs your feed subscriptions, folders, and reading activity through SereneReader servers so they stay consistent across your devices and the web app. Subscriptions purchased in the apps are processed by Apple; purchases made on the web are processed by our payment provider. SereneReader's data practices are covered in full by its own policy at serenereader.com/privacy, which governs wherever the two documents differ.

Pulse: Widgets for GA4 (Google User Data)

Our app Pulse connects to your Google account using the read-only scope analytics.readonly so it can display your Google Analytics data on your devices. Specifically:

  • Access. Pulse reads Google Analytics reporting data and your list of Analytics properties. Access is read-only; Pulse cannot change anything in your Google account.
  • Use. Data is retrieved directly from Google's APIs to your device and used solely to display your statistics in the app, its widgets, the Apple Watch app, and the Mac menu bar.
  • Storage. Sign-in tokens are stored in your device's Keychain, and recent statistics are cached on your device so widgets can display them. Nothing is stored on JonesLabs servers, because the app has none.
  • Security. Google user data is protected in transit by TLS (all requests go directly from your device to Google's APIs) and at rest by your device's Keychain (sign-in tokens) and the app's sandboxed on-device storage (cached statistics). No Google user data is ever stored on JonesLabs servers; the app has no server component.
  • Sharing. We do not transfer Google user data to JonesLabs or to any third party, do not use it for advertising, and do not use it to train AI or machine-learning models. Pulse's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
  • Revocation and deletion. Signing out in the app deletes its tokens and cached data, and deleting the app removes everything it stored. You can also revoke Pulse's access at any time at myaccount.google.com/permissions.

SiteGrade: Security Check

SiteGrade checks the security configuration a website serves to browsers and grades it A to F. Its Apple privacy label is "Data Not Collected," and that is accurate because the app has no server component, no accounts, and no third-party SDKs:

  • Nothing is sent to JonesLabs. There is no SiteGrade server, no account system, and no analytics. The URLs you check, your reports, and your history never reach us.
  • What leaves your device. When you run a check, your device contacts the website you entered on ports 443 and 80 and performs DNS lookups for that host. This is the same traffic a browser makes when it opens the page. The site you check receives a request from your device, which is you contacting a third party of your own choosing.
  • Storage. Reports and history are stored on your device only. A shared app group container holds two things: a URL handed off from the share extension, and a flag recording whether Pro is unlocked. The share extension makes no network requests of its own.
  • The mixed-content check. To find insecure subresources, SiteGrade loads the page once in an off-screen web view that is never displayed and uses a non-persistent data store, so cookies, storage, and browsing history from the checked page are discarded when the check ends.
  • Purchases. The Pro unlock is a one-time purchase processed entirely by Apple through StoreKit. There is no server-side receipt validation and we never see your payment details or identity.
  • Deletion. You can delete individual reports or your entire history inside the app, and deleting the app removes everything it stored.

Boost Weather

Boost Weather gives you an air read for driving: temperature, dew point, pressure, elevation, and a Green, Yellow, or Red verdict against your car profile. It runs on iPhone and Apple Watch, with Home Screen and Lock Screen widgets and watch complications.

JonesLabs runs no server for Boost Weather and receives no data from it. The app has no accounts or sign-in, no analytics, no advertising, no tracking, and no third-party SDKs. Its App Store privacy label lists no data used to track you, and lists Precise Location under "Data Not Linked to You," used for App Functionality. The app's privacy manifest declares the same.

  • Location. The app asks for precise location, When In Use only, and never uses it in the background. It uses your location to fetch the weather, to read your elevation, and to record where each reading was taken. Widgets and watch complications use the system's widget location permission to fetch the weather where your iPhone or Apple Watch is. Your location is sent only where this section describes, and never to JonesLabs. The app works fully without location: you can type the values yourself in Manual mode or pick a saved place.
  • Drive mode. When you turn Drive mode on, the app watches your GPS speed only while it is open and on screen, so it can apply the highway offset you set. It stops the moment the phone locks or the app leaves the screen. Speed is never recorded, stored, or sent anywhere.
  • Apple Weather (WeatherKit). To get current conditions and the forecast, the app sends Apple the coordinates of your device or of a saved place. The iPhone app, the Apple Watch app, and the widgets each make their own requests.
  • Apple Maps (MapKit and Core Location). When you add a saved place, the text you type in the search goes to Apple. To show a place name, the app sends coordinates to Apple for reverse geocoding and keeps the names on your device for 24 hours. While the radar map is open, Apple Maps supplies the base map tiles for the area shown.
  • U.S. Geological Survey elevation. When you add a saved place in the United States and leave its elevation blank, the app sends that place's coordinates to the USGS Elevation Point Query Service (epqs.nationalmap.gov) to look up its elevation. Places outside the United States are never sent. This is a free U.S. government service with public-domain data that needs no API key.
  • NOAA radar. The radar map shows National Weather Service radar from NOAA (mapservices.weather.noaa.gov), a free U.S. government service with public-domain data that needs no API key. While the map is open, the app requests radar images for the area on screen. Each request includes a map tile's bounding box, which reveals the approximate region you are viewing. The map opens centered on the place of the current reading: where you are, or a saved place. The map button appears only in the United States and its territories.
  • What these services see. Like any web request, the requests above also show each service your device's IP address and standard request headers. Their own privacy policies apply: Apple's, USGS's, and NOAA's.
  • Stored on your device. The latest reading, including its coordinates and place name, is kept in a cache shared with the app's own widgets. Your settings, including the values you type in Manual mode, are stored on the device. So is your list of saved places (custom locations) with their coordinates, which is not synced anywhere.
  • Barometer and altimeter. Reading your device's barometer and altimeter is off by default. If you turn it on, the readings stay on your device.
  • Stored in your iCloud account. If you are signed in to iCloud, the app stores your car profiles, your snapshots, and three settings (the active profile, the unit system, and the snapshot text template) in its private CloudKit database in your own iCloud account. A snapshot is a saved reading with its time, coordinates, place name, values, verdict, and your notes. JonesLabs cannot read this data.
  • iPhone and Apple Watch. The two apps talk to each other directly through Apple's WatchConnectivity, not through any JonesLabs server.
  • AI analysis. On devices with Apple Intelligence turned on, the "why" page can show a short written analysis of the checks your profile ran. Apple's on-device Foundation Models generate it entirely on your device. It works offline, nothing is sent anywhere, and you can turn it off in Settings.
  • Sharing. The app shares a snapshot only when you tap Share. It goes, as text or JSON, wherever you send it, and can include the snapshot's coordinates and your notes.
  • Ratings and crash reports. App Store rating prompts use Apple's system dialog, and no data from them comes to us. Crash and diagnostic data reaches us only if you turn on "Share With App Developers," a device-wide Apple setting. The app has no crash-reporting SDK.
  • Purchases. Boost Weather is paid up front on the App Store, and Apple processes the purchase. There are no in-app purchases and no subscription, and we never see your payment details or identity.
  • Support. If you contact us about Boost Weather, we have what you send, and we handle it as described under Support above. You can reach us through our contact page.
  • Deletion. You can delete individual profiles, snapshots, and saved places in the app. "Reset app" in Settings deletes the app's data, including the copies in your iCloud account. Deleting the app removes what it stored on that device; to also delete the iCloud copies, use Reset app first.

Data Security

We take reasonable measures to protect information transmitted through the Site. All traffic is served over HTTPS with HSTS preloading. We implement Content Security Policy headers, input sanitization on all form submissions, and rate limiting to prevent abuse. Contact form data is sanitized with DOMPurify before processing.

Data Retention

Contact form submissions are delivered to us via email and retained in our email inbox. We do not store form submissions in a separate database. IP addresses used for rate limiting are held in server memory for up to 15 minutes and are not persisted.

Your Rights

You may request access to, correction of, or deletion of any personal information we hold about you. To make a request, use the contact form on the Site. We will respond within 30 days.

If you are located in California, the European Economic Area, or another jurisdiction with applicable data protection laws, you may have additional rights under those laws.

Children's Privacy

The Site and the Apps are not directed at children under the age of 13, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.

Changes to This Policy

We may update this privacy policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Continued use of the Site or the Apps after changes constitutes acceptance of the updated policy.

Contact Us

If you have questions about this privacy policy or how we handle your data, contact us at:

JonesLabs LLC
8735 Dunwoody Place #12250
Atlanta, GA 30350
Email Us
706-730-2025